59 lines
2.7 KiB
Markdown
59 lines
2.7 KiB
Markdown
# Releasing ForgeFlow
|
|
|
|
ForgeFlow releases are built only from a clean, reviewed commit on Node 22 LTS.
|
|
|
|
The private source repository publishes a curated snapshot to `Jens/ForgeFlow-Public`. A version change on its `main` branch triggers the Windows release workflow. The workflow checks the public-source manifest, runs the quality and browser gates, builds both Windows artifacts, signs the release manifest with the existing publisher key, and publishes the release after all required assets are present. A source-only change does not create another binary release. The legacy `Jens/ForgeFlow` repository remains available for the 0.10.16 updater bridge.
|
|
|
|
## Quality gate
|
|
|
|
```powershell
|
|
npm ci
|
|
npm run quality
|
|
npm audit --omit=dev --audit-level=high
|
|
```
|
|
|
|
## Windows build — no paid services required
|
|
|
|
ForgeFlow is a personal/internal tool. The supported release path therefore has
|
|
no certificate, Azure or other paid-service dependency:
|
|
|
|
```powershell
|
|
npm run dist:win
|
|
```
|
|
|
|
Run `npm run signing:setup` once on the release workstation. It stores the
|
|
private Ed25519 key outside the repository and writes only its public key into
|
|
the packaged app. `npm run dist:win` then produces the installer and portable
|
|
executable, SHA-256 sidecars, CycloneDX SBOM, provenance and an Ed25519-signed
|
|
manifest bound to the exact source commit. The updater verifies the pinned
|
|
publisher key before trusting the artifact digest and verifies that digest again
|
|
immediately before replacing the installed executable.
|
|
|
|
Windows can display an `Unknown publisher` warning for an unsigned installer.
|
|
That warning concerns public publisher reputation; it does not prevent ForgeFlow
|
|
from installing or using its checksum-verified in-app updates. Authenticode can
|
|
be added later as an optional distribution convenience, but is not required for
|
|
correct operation.
|
|
|
|
## Atomic publication
|
|
|
|
`npm run release:binary` keeps the Gitea release in draft state while uploading
|
|
the installer, portable executable, two checksums, provenance, SBOM, signed
|
|
manifest and signature. It only publishes after all eight assets are present. A
|
|
failed upload leaves a draft rather than exposing an incomplete updater target.
|
|
|
|
The optional signing acceptance fixture can still validate the complete local
|
|
Authenticode chain without purchasing or retaining a certificate:
|
|
|
|
```powershell
|
|
npm run test:signing
|
|
```
|
|
|
|
This disposable fixture signs installer, portable, update-helper and uninstaller
|
|
stand-ins, requires an RFC 3161 timestamp, and proves rejection of a missing
|
|
timestamp, wrong publisher and a modified binary. Its certificate is removed
|
|
from the current-user certificate store after the test.
|
|
|
|
The disposable test certificate is removed from the current-user certificate
|
|
store after the test and is never used for a published build.
|